Vulnerability CVE-2021-26828


Published: 2021-06-11

Description:
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

See advisories in our WLB2 database:
Topic
Author
Date
High
ScadaBR 1.0 / 1.1CE Windows Shell Upload
Fellipe Oliveira
13.05.2021

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

 References:
http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4
http://packetstormsecurity.com/files/162564/ScadaBR-1.0-1.1CE-Linux-Shell-Upload.html
https://youtu.be/k1teIStQr1A

Copyright 2024, cxsecurity.com

 

Back to Top